Splunk Search

Heavy Forwarder Search

fmcgheeSplunk
Splunk Employee
Splunk Employee

i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data to indexers. 

 

Context - Upgrade readiness app has identified several apps that are not supported or in need of upgrade. Need to see if these apps are needed any longer and can be removed or truly need to be upgraded prior to the Splunk version upgrade of the HWF. 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it's not apps that send data, it's your forwarders 😉

But seriously - for data originating on this forwarder, you can just check which inputs are enabled and which are disabled so you can at least verify which inputs are definitely "not needed. Unfortunately, maybe short of some heavy debug, there is not even possible to know which way the event passed through so if you have HF processing data from some set of UF unless you know which UF's are supposed to output to this particular HF, you can't tell it from the resulting indexed event.

Having said that - if you're asking in context of upgrading to python3 and we're talking about HF, you probably mean which modular inputs are in use. I'd just do a btool inputs list and check which ones are enabled.

Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...